Jump to content

Recommended Posts

Posted
Our admin and curriculum servers share the same network and the subnet mask was 255.255.255.0. When we had county broadband installed they didn't mention changing this but the LEA support team recommended changing the admin subnet to 255.255.252.0. I need more curriculum IP addresses so I asked the County Broadband team about changing the curriculum subnet and they said it should be 255.255.252.0 However, I'm considering changing it to 253.0 which will give me more than enough IP addresses and will help segregate the admin and curriculum systems. Does this make sense or am I barking?
Posted

253.0 is verboten! you can do 252.0 or 254.0, but not 253, because of the way the bits fall. A quick cuttypasty from a recent thread:

 

... That is, you can have a subnet mask of (say) 255.255.252.0 which will give you approx 4 times your current address space:

 

11111111.11111111.11111111.00000000 = 255.255.255.0 - current setting

11111111.11111111.11111110.00000000 = 255.255.254.0 - ~2x as many hosts

11111111.11111111.11111100.00000000 = 255.255.252.0 - ~4x as many hosts

11111111.11111111.11111000.00000000 = 255.255.248.0 - ~8x as many hosts

  • Thanks 1
Posted

The possible problems are that the larger ip address range you want might overlap with another school and therefore you can't have it.

 

They might be willing to give you a completely different range to work with - liaise with them but be assertive about your ip range needs and see what they offer you.

 

regards

 

Simon

Posted

For the sake of your sanity I cannot stress enough that you get them to confirm the range they give you is NOT in use by another school.

 

In the summer I requested an entirely new larger range. So I ring the LEA IT boys up "of course sir, here's your new IP range. Let me just check our Excel 97 spreadsheet to make sure it's not allocated to another school. Ah, it isn't. enjoy". 2 weeks later at the start of term,our printers are spewing out crap from other schools. Turns out they hadn't updated their little spreadsheet for a while and had given us someone elses range!!

Posted
For the sake of your sanity I cannot stress enough that you get them to confirm the range they give you is NOT in use by another school.

 

In the summer I requested an entirely new larger range. So I ring the LEA IT boys up "of course sir, here's your new IP range. Let me just check our Excel 97 spreadsheet to make sure it's not allocated to another school. Ah, it isn't. enjoy". 2 weeks later at the start of term,our printers are spewing out crap from other schools. Turns out they hadn't updated their little spreadsheet for a while and had given us someone elses range!!

 

LOL - oh thats a classic.... :D:D

Nothing like a 'change management process' is there ?

Posted

You should be using non routable IP addresses

that way the school down the road could be using exactly

the same addresses and it wouldn't matter. Your LEA/Council

would then map your internal default gateway to external ones

via their firewall ( the same way your broadband works at home but

just on a bigger scale )

 

see

 

http://mtmnet.com/PDF_FILES/NonRoutableIPaddresses.PDF

 

no way in the world should someone be able to print to your printers

of even ping an address on your network. If you use one of these

reserved addresses you can have a subnet mask of something

like 255.255.0.0 and have loads of addresses

 

If you are using real (as in routable) ip addresses then you'd better know

exactly what you are doing. If your LEA/Council are telling you to use

routable ip addresses and giving out overlapping or already used ip

addresses then they need to be taken out into the playgound and beaten up

 

M

Posted

It makes perfect sense bar the 3, if the admin machines are already using this subnet mask then the stations will have spread out into this new address space already and should have thrown some errors by now.

 

- Using information from your previous post -

Your address space with a subnet mask of 255.255.252.0 is between 10.91.4.1 and 10.91.7.254 this gives you 1022 avalible addresses all in the same subnet. The ip broadcast address is 10.91.7.255 and the network address is 10.91.4.0 .

Posted

What i find really difficult is that the LEA or service provider goes all the way to the wqorkstation ip address level where they should just terminate the connection at the permiter of the school's network. This way the school can design and use thier own IP addressing scheme without any effect on other schools etc. There is absolutely no need for RBCs or LA to go down to the workstation level on the school's PCs. I understand from filtering control but still think they should just leave it at the permiter and allow schools to NAT their connections.

 

I've seen so many implementation where the overlap in IP addresses has caused so much confusion and ongoing troubleshooting.

 

Ash.

Posted
It makes perfect sense bar the 3, if the admin machines are already using this subnet mask then the stations will have spread out into this new address space already and should have thrown some errors by now.

 

- Using information from your previous post -

Your address space with a subnet mask of 255.255.252.0 is between 10.91.4.1 and 10.91.7.254 this gives you 1022 avalible addresses all in the same subnet. The ip broadcast address is 10.91.7.255 and the network address is 10.91.4.0 .

 

The above IP range uses CIDR method (classless).

 

Ash.

Posted

We're currently on a subent of 10.4.28.xxx /23 giving us 510 pssoble hosts....

 

but we're running out - what iwth PCs, servers, and various other IP devices (printers, cameras, etc..) so in process of moving to a new range of 192.168.1.1 to 192.168.9.254

 

With servers, printers, etc on the 192.168.0.xx range..

 

Just need to get Smoothwall to allow computers through on that range - if i can get the internal alias properly configured..

Posted
What i find really difficult is that the LEA or service provider goes all the way to the wqorkstation ip address level where they should just terminate the connection at the permiter of the school's network. This way the school can design and use thier own IP addressing scheme without any effect on other schools etc. There is absolutely no need for RBCs or LA to go down to the workstation level on the school's PCs. I understand from filtering control but still think they should just leave it at the permiter and allow schools to NAT their connections.

 

I've seen so many implementation where the overlap in IP addresses has caused so much confusion and ongoing troubleshooting.

 

This is true, and I agree. But I also agree with and accept that the LEA distributes address ranges. NAT'ing isn't possible here due to various technical and political reasons and I'm guessing other establishments have the same problem. I do recall in the BECTA technical specs that the LEA or RBC should be responsible for address ranges.

 

Problems only ocurr such as in my case they hadn't been keeping their documentation up to date.

Posted (edited)
What i find really difficult is that the LEA or service provider goes all the way to the wqorkstation ip address level where they should just terminate the connection at the permiter of the school's network. This way the school can design and use thier own IP addressing scheme without any effect on other schools etc. There is absolutely no need for RBCs or LA to go down to the workstation level on the school's PCs. I understand from filtering control but still think they should just leave it at the permiter and allow schools to NAT their connections.

 

I've seen so many implementation where the overlap in IP addresses has caused so much confusion and ongoing troubleshooting.

 

Ash.

 

Ofcourse overlapping ip address space isn't an issue when MPLS VPN's and VRF tables are deployed in the WAN. Although i'd imagine you can count on the digits on one hand the number of authorities who've transitioned to MPLS VPN's - most are probably still stuck on the p2mp hub and spoke model and eigrp routing.

Edited by torledo
Posted
It makes perfect sense bar the 3, if the admin machines are already using this subnet mask then the stations will have spread out into this new address space already and should have thrown some errors by now.

 

- Using information from your previous post -

Your address space with a subnet mask of 255.255.252.0 is between 10.91.4.1 and 10.91.7.254 this gives you 1022 avalible addresses all in the same subnet. The ip broadcast address is 10.91.7.255 and the network address is 10.91.4.0 .

 

We have static addressing throughout at present, hence my reason for wanting more addresses. So everything will still be within the range 10.91.4.1 - 255. If you read my previous post, I never managed to get DHCP to run on the curriculum server and ran out of time so I just stuck with static addresses. That has become more of a bind as the network has grown, so I plan to spend the holidays sorting out DHCP. What I then want to do is create a DHCP range big enough to take all of the curriculum computers (150 will do) and then I can just go round and reset the computers to DHCP at my leisure. So if I read this right, 255.255.254.0 will give me 10.91.5.1-255 to play with?

Posted (edited)
So if I read this right, 255.255.254.0 will give me 10.91.5.1-255 to play with?

 

A 255.255.254.0 mask will give you 510 addresses in the address space. the starting ip depends on what you get allocated.

 

.255.0 = 254 hosts

.255.128 = 126 hosts

 

As sahmeepee said its all about the binary

 

Didn't remember that you had said that you went static, just recalled that I had given an answer to a similar question http://www.edugeek.net/forums/showthread.php?t=14946&page=2

Edited by SYNACK
Posted

I'll give you two answers on this ... one from the LA/RBC point of view and the other from an independently minded school.

 

Firstly, there are so many reasons why you should use an RBC based addressing system, including the fact that an RBC is a WAN ... and dirty great big one, but a WAN nonetheless. The idea is to ensure that schools within and LA and within a region have the best possible connectivity to each other as well as the best possible connectivity to the National Education Network.

 

QoS and Cos are set up with each RBC and across JANET and the NEN ... if a school starts closing itself off then it makes life more difficult for everyone involved, especially when it comes to ensuring all services are viable. To make best use of the available services and to ensure teh best levels of security sticking by the set guidelines is best.

 

JISC and JANET have a number of papers about all of this and they are easily obtainable.

 

There are a number of examples of good practice for the use of supernetting and VLANs if required, but NAT should not really be used within a small institute (anything around /19 or below should be considered small according to a JANET session circa 2004)

 

---------

 

And now from a different viewpoint.

 

Why the heck should I be dictated to? I don't want to spend weeks (or months) waiting for additional ranges, only to find they are not concurrent, I have to make further changes internally and then have to jump through hoops to get the right access to the outside world for them.

 

Why can't I just put my own firewall in? At tleast that way if a DoS attack is being launched from my school it is likely to get caught by my kit and not affect the rest of the RBC? Does it really matter that you can't track which specific machine is making a request to the internet or to a service? I'm sure I could do it instead.

 

--------

 

Both fairly good arguements ... and with valid points ... but the idea of being in an RBC is agreeing to the rules that they set. There is nothing wrong with challenging those rules and coming up with your own ideas but there are times you have to accept that it will limit you instead.

 

I have my own firewall and NAT. All traffic goes out via the WAN face of that device and so has that IP address ... apart from a few boxes that have one-to-one NAT setup (internet facing servers such as web servers, proxy / cache, etc).

 

The limitations include a difficulty with LA based Video Conferencing, knowing that when it is available after the present changes I will not be able to do LAN logins that are hooked into the Regional IDP ... so no federation of services ... and not forgetting the whole "you are not a standard network build so it will take longing to work out where your problems are" thing. I accept this at the moment.

 

So ... what is best for your school? Damned if I know ... I just know what is best for mine ... at the moment ... and that will change over the next 3 years.

 

I'll tell you something else ... these splinters from sitting on the fence ... they don't half hurt!

Posted
at the start of term,our printers are spewing out crap from other schools. Turns out they hadn't updated their little spreadsheet for a while and had given us someone elses range!!

 

 

Hmmmm, tempting to use this little 'feature' on the day I leave.............

Posted

I think the idea of an *enforced* RBC wan is a complete farce. I go for the second viewpoint.

 

We are already severly restriced, I would even say hampered by the services offered by the RBC. Getting unintentional traffic from someone elses lan is beyond unreasonable.

 

I have a range, I use exactly 1 ip in it, our firewall. Actually I use 7 as it manages multiple forwarding ips comming in from the "real" internet.

 

We also have no QoS options available. Mail service is a joke, cost is far too high these days, ntp server often stops working and filtering is from the stone age. I've also had 2 1/2 days (concurrent) down time already this year.

 

You will have to excuse me if I think RBC are a bad idea, but if you used segfl you would think so too!

 

And finally, whats the point of virus scanning an attachment if YOU ARE GOING TO DELETE IT ANYWAY! (these options are helpfully unchangeable and set on a RBC level)

Posted (edited)
You should be using non routable IP addresses

that way the school down the road could be using exactly

the same addresses and it wouldn't matter. Your LEA/Council

would then map your internal default gateway to external ones

via their firewall ( the same way your broadband works at home but

just on a bigger scale )

 

Sorry Interele to contradict, but all IP addresses are in fact routable.

It's just that certain ranges were excluded from Internet use by RFC1597 in 1994.

These are sometimes refered to as "Non-Routable" but effectively this just means "Private".

 

Most of the National Grid for Learning already operates on Private "non-routable" addresses.

 

These are all inter connected some via a Metro VPN arrangement allowing the LEA's to manage/control connectivity between the various schools and the internet under their jurisdiction.

 

Most of the Broadband Consortiums follow the guidelines that were origionally set up far too many years ago by JANET, BT and oh yes, two guys from RM.

 

Each school was initially allocated just 2 subnets, 255 addresses for Admin and another 255 for the Curriculum as this was all that was ever envisaged they would need!

The subnets needed to be able to route between each other if desired and allow the LEA to route easily between the other schools connected to their Metro VPN.

Effectively, a fully routable network but using private address ranges.

 

Fortunately, the planners did have the savvy to group them so that each school could if need be have 4 Subnets for Curriculum and 2 for Admin.

 

Now even these are under stress.

 

With so many schools requiring bigger and bigger networks we now have site admins establishing IP networks independently of the LEA guidelines that end up performing NAT behind NAT which only complicates an already difficult to manage system.

 

Your perspective (Interele) it seems is, as many people think, that beyond your edge device is the internet, a public IP either directly assigned to your firewall or mapped by forwarding or VLAN when in fact, you may be several hops or more downstream of a public facing internet address.

 

In London as the LGFL spans dozens of LEA's via the Synetrix system they call it Virtual Firewalling, carried out at L2/3, whereas in Herts there is the additional ability to route at L4.

 

Therefore dependent on where you work the simplest task of getting a port redirected will take several applications written in blood, followed by a seven week period of fasting and possibly resulting in you having to sleep with the firewall administrators gay cousin!:eek:

 

To the thread starter,

Changing your internal subnet mask will not help you as you would also need to modify the gateway devices settings in order to route your packets correctly. This device is not under your management but that of your broadband consortium.

Mess with your internal subnet masking without prior approval from your LEA or RBC, may result in your Internet connection being suspended until the changes are corrected and a severe bollocking from the LEA's MIS department.

 

Yes it sucks! But rules is rules and anarchy is not an option.

Edited by m25man
Typo
  • Thanks 1
Posted

One thing that I would like people to remember is that there is a lot of presumption that all schools have staff, and that those staff are happy setting up their own firewalls, getting NAT going, configuring QoS and CoS within their own network ...

 

We are forgetting about the schools with no tech support other than someone shared a day or so a week, who may not have time or resources to do more bespoke work, or schools with just crap support.

Each of these are likely to mean a school would get a better service by sticking to the guidelines.

Posted

To the thread starter,

Changing your internal subnet mask will not help you as you would also need to modify the gateway devices settings in order to route your packets correctly. This device is not under your management but that of your broadband consortium.

Mess with your internal subnet masking without prior approval from your LEA or RBC, may result in your Internet connection being suspended until the changes are corrected and a severe bollocking from the LEA's MIS department.

 

Yes it sucks! But rules is rules and anarchy is not an option.

 

The gateway is 255.255.252.0 it was just nobody told me when it was installed so we stuck with 255.255.255.0 until the admin server was replaced and that was changed to 252.0. So I can't see any problem with putting the curriculum subnet to 254.0 it will simply give me a smaller range within the range. Or would I be best changing that to 252.0 and be done with it?

Posted
One thing that I would like people to remember is that there is a lot of presumption that all schools have staff, and that those staff are happy setting up their own firewalls, getting NAT going, configuring QoS and CoS within their own network ...

 

We are forgetting about the schools with no tech support other than someone shared a day or so a week, who may not have time or resources to do more bespoke work, or schools with just crap support.

Each of these are likely to mean a school would get a better service by sticking to the guidelines.

 

Hi Tony,

 

Yes i agree with this and for those schools the RBC "way of doing things" does come in handy for them. I still think for larger schools with higher skill set technicians and NMs there should be some flexibility in regards to this. The difficulties that arises is that when a schools runs out of the allocated ranges and they want to extend the range. If RBCs are playing their cards right then they should have a plan for this so this scenario is covered and a step-by-step guide is provided to school who's been re-allocated a new range of extended their range. This will allow the school's tech team/dept. to implement the changes as quickly as possible and with mimimal distruption.

 

I still don't like the RBC/LEA want to see right down to the school's workstation level, i personally don't see any reason for this except the firewall/filtering, which can be handled at the school permiter.

 

Ash.

Posted
The gateway is 255.255.252.0 it was just nobody told me when it was installed so we stuck with 255.255.255.0 until the admin server was replaced and that was changed to 252.0. So I can't see any problem with putting the curriculum subnet to 254.0 it will simply give me a smaller range within the range. Or would I be best changing that to 252.0 and be done with it?

 

Unless you plan to split up the network further internally to lower broadcast traffic then I suggest that you just set it up to be able to use all of your avalible addresses. That way if you get lots more stuff that is IP enabled you won't need to go through the expansion process again.

Posted
Hi Tony,

 

Yes i agree with this and for those schools the RBC "way of doing things" does come in handy for them. I still think for larger schools with higher skill set technicians and NMs there should be some flexibility in regards to this. The difficulties that arises is that when a schools runs out of the allocated ranges and they want to extend the range. If RBCs are playing their cards right then they should have a plan for this so this scenario is covered and a step-by-step guide is provided to school who's been re-allocated a new range of extended their range. This will allow the school's tech team/dept. to implement the changes as quickly as possible and with mimimal distruption.

 

I still don't like the RBC/LEA want to see right down to the school's workstation level, i personally don't see any reason for this except the firewall/filtering, which can be handled at the school permiter.

 

Ash.

 

The procedure for requesting additional ranges was actually written some time ago, but has only just started to be put into practice. It will be clear how it fits in after the end of March once the new Standard Network Build documentation is out (or sooner hopefully).

 

IP control down to the desktop is one of those things that some like and others don't. Once you start getting into federation between school, the Regional IDP (ie the RBC) and 3rd party companies ... then you need it down to client level ... that is the way the whole federated access management is configured to be most efficient and most cost effective.

 

That is the other problem with all this ... whilst it might only be a bit of extra work for you considering your own setup ... if a raft of schools all have something different then this can put an extra burden on the LA / RBC support provider ... and all we then get is a lot of moaning about x doesn't work and y is too costly.

 

Roll on April!

Posted
The procedure for requesting additional ranges was actually written some time ago, but has only just started to be put into practice. It will be clear how it fits in after the end of March once the new Standard Network Build documentation is out (or sooner hopefully).

 

IP control down to the desktop is one of those things that some like and others don't. Once you start getting into federation between school, the Regional IDP (ie the RBC) and 3rd party companies ... then you need it down to client level ... that is the way the whole federated access management is configured to be most efficient and most cost effective.

 

That is the other problem with all this ... whilst it might only be a bit of extra work for you considering your own setup ... if a raft of schools all have something different then this can put an extra burden on the LA / RBC support provider ... and all we then get is a lot of moaning about x doesn't work and y is too costly.

 

Roll on April!

 

Tony

 

Could you explain what you mean by federation between schools. And examples of how this is used or needed.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...